CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

YouTube AI Bot Scam Drains 274 ETH from 224 Victims

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING YouTube AI Bot Scam Drains 274ETH from 224 Victims

A coordinated YouTube campaign, dressed up as coding tutorials for an AI-powered crypto arbitrage bot, has stolen 274.60 ETH (approximately USD 517,205) from 224 victims between February and August 2026. Blockchain intelligence firm TRM Labs traced the funds to six shared collection addresses, indicating a single operation behind what appeared to be nine separate creator channels. For accounting firms, auditors, and CFOs handling digital asset portfolios, this case is a direct lesson in why transaction-level review and smart contract due diligence cannot be optional.

YouTube AI Bot Scam Drains 274 ETH from 224 Victims

How the Scam Works: A Tutorial That Turns Victims Into Attackers

The campaign exploits a genuinely plausible premise. AI coding assistants do help developers write and deploy software, including trading applications. The tutorials promise to show viewers how to build a "fully autonomous crypto trading bot from scratch" using Claude, Anthropic's AI assistant, with no prior experience required. That pitch lands because it is not entirely implausible on its face.

The Legitimate Steps Before the Trap

Victims are walked through a standard-looking setup: create a wallet, paste provided source code into what appears to be a compiler, deploy a smart contract, and fund it with enough cryptocurrency to "start arbitrage." Every step looks routine. The open-source code shown on screen is clean, containing nothing suspicious. Wallet security warnings do not fire. No phishing link appears. No malicious approval prompt is presented. The victim deploys a contract they believe they own and authorises each transaction from their own wallet.

The Single Malicious Step Hidden in Plain Sight

The trap is the compiler. Rather than directing viewers to an established development environment such as the genuine Remix IDE, the tutorials link to a custom site styled to look identical to Remix but controlled by the operators. When the victim pastes the displayed source code, a background script discards it entirely and compiles a different contract fetched from the operator's server. The bytecode that actually reaches the blockchain is a honeypot: it accepts deposits and forwards any balance above 0.05 ETH to the operator the instant the victim presses "Start" or "Withdraw," which is precisely the button the tutorial instructs them to press. Nothing in the browser indicates the substitution has occurred.

TRM identified 234 smart contracts deployed and funded by victims across the campaign period, with flows ultimately concentrating into six operator-controlled addresses. The stolen funds then moved entirely through decentralised finance protocols, cross-chain bridges, and a mixer, with no centralised exchange appearing in the chain. That routing is deliberate: it bypasses the withdrawal screening and KYC checks that centralised venues apply.

Coordinated Production Behind a Fake Multi-Creator Facade

The nine YouTube tutorials were presented as the work of independent creators, but TRM's analysis found clear signs of shared production. Scripts are nearly identical across channels. On-screen instructions follow the same sequence. Multiple videos displayed the same claimed profit figure down to the decimal, including a return of 1 ETH every 20 hours. AI-generated presenters and synthesised voices were used to create the appearance of distinct creators, with some videos pairing an AI avatar speaking directly to camera and others combining a synthetic voice with a screen recording.

Written Guides and Infrastructure Spread Across Major Cloud Hosts

The companion written guides linked in video descriptions were hosted across Telegram, Amazon S3, and Google Cloud Storage. Despite differences in visual design and specific links, the instructions followed the same order and ended at the same step: fund the bot with sufficient liquidity and press Start. Using major cloud infrastructure lends the guides an air of legitimacy and makes simple URL-based blocklisting ineffective.

Many videos also obscured URLs shown on screen and directed viewers to description links instead, meaning a single screen recording could be reused across channels while the destination address was quietly rotated. As of September 2026, the nine videos remained online and had accumulated 310,474 views since the earliest was posted in April 2026. Earlier versions using ChatGPT as the lure rather than Claude have since been removed from YouTube, confirming the operation extends beyond the nine tutorials in TRM's current analysis.

The Secondary Drain: A Fake Error Message

Once funds are gone, the operators attempt a second extraction. One compiler site displayed a scripted error message after the drain had already occurred: "ERROR: Arbitrage stuck — Gas nonce liquidity equals injected liquidity. Add 50% of your original liquidity (up to 1 ETH) as arbitrage gas to your bot's smart contract, then press Start again." "Gas nonce liquidity" is not a recognised Ethereum concept, and no such error exists in the deployed contract. The message exists solely to prompt a second transfer from a victim who is confused rather than certain they have been robbed.

Why Conventional Defences Do Not Catch This

Standard wallet security tooling is built around a specific threat model: a hostile external site requesting a malicious approval signature, or a phishing domain impersonating a legitimate service. This campaign circumvents every layer of that model.

The Gaps This Attack Exploits

Phishing blocklists do not flag a victim's own compiler session. Approval-signature analysis sees nothing unusual because the victim is authorising a contract they believe they built and own. Wallet warnings are silent because the transactions are self-initiated. The malicious bytecode substitution happens server-side before deployment, invisible to browser-level inspection. Even a technically informed user reviewing the source code on screen would see nothing wrong, because that code never reaches the chain.

TRM's broader intelligence context adds weight to the concern. The firm found criminal adoption of AI rising 40% year on year, with scammers leading that adoption. Scamming is described as one of the frontiers where AI use has reached a mature stage, present across every phase of the attack lifecycle. The shift from ChatGPT branding in 2025 to Claude branding in 2026 illustrates how operators can refresh the AI-brand lure while leaving the underlying mechanics unchanged, a low-cost iteration cycle that outpaces most defensive updates.

Accounting and AML Implications for Firms and Auditors

For accounting practices with digital asset clients, and for internal finance teams at crypto-native businesses, this typology raises several immediate questions that go beyond incident response.

On-Chain Traceability and the Limits of Self-Reported Transactions

Victims in this campaign deployed and funded contracts from their own wallets and authorised every step. From a raw transaction-history perspective, those outflows look indistinguishable from a deliberate DeFi interaction. A client presenting their wallet history may not even know they were defrauded, particularly if the secondary error message prompted them to send a second tranche believing they were fixing a technical problem.

Firms using robust crypto accounting software that ingests raw on-chain data will see the contract deployment and the outbound transfer. Without context, those entries will be classified as DeFi activity, not theft. That misclassification matters for two reasons: it affects the P&L treatment of the loss, and it can distort AML transaction monitoring if the firm is also reporting suspicious activity. Auditors reviewing digital asset disclosures need to ask clients specifically whether any smart contract interactions during the period involved third-party compiler tools or tutorial-linked code, because standard reconciliation will not surface the distinction.

Smart Contract Due Diligence as a Control Requirement

The attack exposes a gap in most firms' digital asset control frameworks. Policies typically address custody, key management, and exchange counterparty risk. Fewer address the risk of deploying unaudited third-party smart contracts, particularly where the deployment was initiated by a staff member or client following publicly available instructions. The TRM findings are a basis for updating those policies to require that any smart contract deployment touching firm or client funds must originate from a verified development environment, not a tutorial link.

AML Typology Recognition for Compliance Teams

The fund-flow pattern here is worth embedding in compliance team typology libraries. Funds move from victim wallets to honeypot contracts, then to six consolidation addresses, then through DeFi, cross-chain bridges, and a mixer. That layering sequence through decentralised infrastructure, with no centralised off-ramp, is specifically designed to break the transaction trail before any fiat conversion occurs. Compliance officers reviewing suspicious activity reports or preparing SAR narratives in similar cases should note that the absence of a centralised exchange in the chain does not mean the funds are untraceable: TRM's analysis demonstrates that blockchain analytics can reconstruct the flow even through mixers and bridges.

For firms whose clients hold ETH or interact with DeFi protocols, a periodic review of wallet activity using digital asset accounting software capable of smart contract interaction tagging is a proportionate response. Transactions that look like DeFi deposits but flow to contracts with no verifiable audit trail or recognised protocol address deserve closer scrutiny.

YouTube AI Bot Scam Drains 274 ETH from 224 Victims

Practical Steps for Firms Right Now

The nine videos were still live as of TRM's September 2026 publication date, with over 310,000 combined views. Earlier variants have been removed, but the operational template clearly persists. Firms should take the following steps without waiting for regulatory guidance to catch up.

Client and Staff Communication

Issue a brief advisory to any clients who interact with DeFi or hold self-custodied wallets. The key message: any tutorial that instructs a user to deploy a smart contract using a third-party compiler site, regardless of how professional that site looks, should be treated as high-risk until independently verified. The fact that Claude or any other AI assistant is mentioned in the title is not a quality signal; it is increasingly a red flag.

Transaction Review and Reclassification

For clients with ETH activity between February and August 2026, flag any smart contract deployments where the contract address does not correspond to a recognised DeFi protocol. Cross-reference against the six operator collection addresses identified by TRM (available in the full TRM report) to determine whether any client funds were affected. If a match is found, the accounting treatment shifts from a DeFi interaction to a theft loss, with different tax and disclosure consequences depending on the client's jurisdiction.

Policy and Control Updates

Update digital asset risk policies to explicitly address third-party compiler tools and tutorial-sourced smart contract code. Pair this with a reminder to staff that AI branding in a tutorial title carries no technical authority. Any deployment of smart contract code using firm or client funds should require sign-off from someone who has reviewed the actual bytecode or obtained an independent audit, not just the source code shown on screen.

Source: TRM Labs

Frequently Asked Questions

FAQ

What exactly is a honeypot smart contract?

A honeypot contract is designed to accept deposits but prevent the depositor from withdrawing them. In this campaign, the contract forwards any balance above 0.05 ETH to the operator's address the moment the victim presses "Start" or "Withdraw," with no mechanism for the victim to recover the funds.

Why did victims' wallets not warn them something was wrong?

Wallet security tools look for phishing sites, malicious approval requests, or suspicious permission signatures. In this scam, the victim self-initiated every transaction from their own wallet against a contract they believed they had built. No external site requested access and no suspicious approval was presented, so standard warnings never triggered.

How should an accountant classify a loss from this type of scam?

The correct classification is likely a theft loss rather than a DeFi interaction or investment loss, though the precise tax treatment depends on the client's jurisdiction and whether the relevant authority treats stolen crypto as a deductible loss. Firms should not leave the transaction coded as a DeFi deposit if the circumstances point to fraud; that misclassification can affect both the P&L and any suspicious activity reporting obligations.

Can blockchain analytics actually trace funds after they pass through a mixer?

TRM's analysis in this case demonstrates that it is possible to reconstruct fund flows through DeFi protocols, cross-chain bridges, and mixers, though the difficulty and confidence level varies. Centralised exchange off-ramps are not required for tracing; sophisticated analytics applied to on-chain data can identify consolidation patterns and operator-controlled addresses even where a mixer is used.

What should a firm do if a client's wallet address matches the victim set identified by TRM?

Reclassify the relevant transactions as a theft loss in the client's records, review whether a suspicious activity report is required under the firm's AML obligations in its jurisdiction, and advise the client on any jurisdiction-specific theft loss deduction or disclosure requirements. The client should also be advised to treat the affected wallet as potentially compromised and to migrate remaining funds to a fresh address.

GLOBALGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Terrorist Financing Shifts to USDT on TRON: 25 Years After 9/11
AML/KYC & Licensing
2.7 Billion Blockchain Spam Transfers: What It Means for Sanctions Screening
AML/KYC & Licensing
US Seizes $61M in Crypto Tied to Iranian Oil Laundering
AML/KYC & Licensing
CoinEx Shuts Down After Nine Years: What It Means for Crypto Accounting